Junglewise Threat Intelligence

stack_collections double free in StackVec::retain on panic

Severity: info · Published 2026-09-22

Vendors: crates.io.

Executive brief

stack_collections is a Rust library providing stack-allocated vector types. A double-free vulnerability in the StackVec::retain method can occur when filtering elements if the filter predicate or a dropped element's cleanup code panics, potentially corrupting memory and enabling denial of service or code execution in affected applications.

Technical details

The vulnerability is a double-free in StackVec::retain caused by unsafe unwinding semantics: self.len is only updated after the entire filter loop completes, so if unwinding occurs mid-loop, the element count remains at its pre-retain value. StackVec's Drop implementation then revisits and double-drops the same slot. This affects only builds with panic unwinding enabled; panic=abort and no_std builds are unaffected. The fix in version 0.3.3 uses an unwind-safe guard similar to std::vec::Vec::retain.

Affected products

  • stack_collections stack_collections 0.3.0 to 0.3.2

Timeline

  • 2026-09-22: disclosed
  • 2026-09-22: patched: Fixed in version 0.3.3

References